India’s data privacy law is no longer a future problem. It is a present liability. These are the five questions your board needs answered before the enforcement clock runs out.
“We are GDPR-compliant, so we should be fine.” - Every General Counsel who hasn’t read the DPDP Rules yet.

Let’s be honest. Most Indian boardrooms treated the Digital Personal Data Protection Act, 2023 as a 2024 problem, then a 2025 problem, and then on November 13, 2025 - the Rules were notified. Enforcement is real. The Data Protection Board of India is operational and is being recruited. And penalties run up to ₹250 crore per violation.

GDPR experience is valuable, but it doesn’t map cleanly onto India’s framework. The DPDPA has its own architecture - consent managers, Data Fiduciary obligations, a phased implementation window running to May 2027, and criminal exposure that goes well beyond civil fines.

The five questions below are the ones your CEO, your board, and your risk committee should have asked already. We’ve ranked them by priority, so you know exactly where to start.

Priority at a Glance

#QuestionPriority
1Consent Architecture - Are your consents legally valid right now?🔴 CRITICAL
2HR & Employee Data - Do your own people’s data meet the standard?🟠 HIGH
3Breach Response - Can you notify in time, every time?🟠 HIGH
4Vendor Chain - Are your processors dragging you into liability?🔵 STRATEGIC
5Significant Data Fiduciary: Are you in the higher-obligation tier?🟢 FORWARD PLAN

 

01

🔴 Critical

CONSENT & NOTICE  ·  IMMEDIATE ACTION

Are the consents we collected before November 2025 still legally valid , and if not, what’s our re-consent plan?

REAL-WORLD SCENARIO

A mid-sized e-commerce brand built its marketing list of 4 lakh customers over three years. The consent checkbox was buried in the signup flow, pre-ticked, and said “By continuing, you agree to our Terms.” The DPDPA requires consent to be free, specific, informed, and unambiguous - obtained through a clear affirmative action. That list is now a liability, not an asset.

The DPDPA is unambiguous: consent must be granular, purpose-specific, and given through a clear opt-in. Pre-ticked boxes, blanket T&C wrap-arounds, and implied consent - the scaffolding most Indian businesses built their user databases on, do not survive scrutiny under the new Rules.

This isn’t just a marketing problem. It affects your CRM, loyalty programme, WhatsApp broadcast list, and SMS campaigns. Every database built on user data. The question isn’t whether you need to re-consent; for most companies, the question is how fast you can execute it without destroying your subscriber base.

₹250 CrMaximum penalty for failure to implement reasonable security safeguards or collect valid consent. Enforcement timelines are live.

The DPDP Rules 2025 also introduce the concept of a Consent Manager - a registered intermediary that maintains records of consent on behalf of users. Larger businesses will need to integrate with this ecosystem. Have you mapped which of your data flows require a Consent Manager?

BOARD-LEVEL ACTIONS THIS QUARTER

→  Commission a consent audit across all customer-facing and employee-facing data collection points.

→  Identify which legacy databases require re-consent versus deletion.

→  Design a re-consent campaign that protects list health while achieving compliance.

→  Build a Consent Management Platform (CMP) or evaluate Consent Manager registration requirements.

 

02

🟠 High

HR & EMPLOYEE DATA  ·  INTERNAL BLIND SPOT

Does our HR department know that employee data is fully covered by DPDPA, and are our biometric attendance systems compliant?

REAL-WORLD SCENARIO

An 800-person manufacturing company uses fingerprint scanners at three factory gates. The data is stored in a central server managed by a third-party vendor. No employee was formally asked for consent. The company assumes this is standard practice. Under the DPDPA, this is a textbook violation waiting to be reported by a single disgruntled employee.

Most CEOs think of DPDPA as a customer-data problem. It is equally an HR problem. Salary details, health records, performance reviews, biometric data, background check reports - all of it is personal data under the Act, and all of it requires a lawful basis for processing.

Biometric data - fingerprints, iris scans, facial recognition - is the most sensitive category. The Act mandates explicit, informed consent before enrollment, encrypted storage, and a clear articulation of the specific purpose. Storing raw biometric templates on a shared vendor server without a Data Processing Agreement is a compounding risk.

₹200 CrPenalty for failing to notify a data breach - which includes an HR system breach exposing employee salary and health data. Internal breaches count.

There is also a criminal dimension that boards routinely miss: if an employee steals or misuses data, the Bharatiya Nyaya Sanhita treats data as moveable property. An employee-perpetrated data breach can attract up to 7 years’ imprisonment  and the company may face vicarious liability if controls were inadequate.

BOARD-LEVEL ACTIONS THIS QUARTER

→  Audit all HR data flows: payroll systems, attendance, recruitment platforms, employee health portals.

→  Review biometric attendance systems; obtain fresh, explicit consent from all enrolled employees.

→  Ensure Data Processing Agreements (DPAs) exist with every HR technology vendor.

→  Train HR leadership on the employee rights framework: right to access, correction, and erasure.

 

03

🟠 High

BREACH RESPONSE  ·  OPERATIONAL READINESS

If we had a data breach tonight, could we notify the Data Protection Board and every affected individual within the prescribed timeline?

REAL-WORLD SCENARIO

A B2B SaaS company’s cloud database is accessed by an unauthorised party on a Friday evening. The security team detects it Monday morning. By the time legal is looped in, the DPO is contacted, the affected users are mapped, and the notification draft is approved it’s Thursday. Under the DPDPA, the clock had already started Friday night. The delay itself is the violation.

DPDPA mandates breach notification to the Data Protection Board of India for every breach - there is no materiality threshold. Unlike some global frameworks where minor breaches can be internally documented, India requires reporting regardless of scale or damage caused. Your incident response process must be pre-built, tested, and board-approved.

The notification must also reach affected individuals promptly - not after legal has spent three weeks crafting the perfect message. Speed and clarity are the compliance standard. Companies that lack a breach playbook will discover its absence at the worst possible moment.

Every BreachMust be reported to the Data Protection Board - irrespective of its gravity or damage caused. There is no de-minimis threshold in Indian law.

The companies that come through data breaches well are those that had a plan before the breach happened. A company seen to have delayed disclosure will face regulatory action and a trust crisis simultaneously.

BOARD-LEVEL ACTIONS THIS QUARTER

→  Build and table-test a Data Breach Response Playbook with clear notification timelines and owners.

→  Map your data assets so you can rapidly identify who is affected in any breach scenario.

→  Pre-draft breach notification templates for both regulator and individual communications.

→  Conduct a simulated breach drill with the executive team - treat it like a fire drill.

 

04

🔵 Strategic

VENDOR & PROCESSOR RISK  ·  SUPPLY CHAIN LIABILITY

Have we audited our data processors - cloud vendors, marketing platforms, payroll providers - and do we have valid contracts with all of them?

REAL-WORLD SCENARIO

A retail chain uses a third-party loyalty management platform that stores purchase history and contact details for 2 lakh members. The platform’s servers are outside India. The contract was signed in 2019 and says nothing about data protection obligations. A breach at the vendor exposes the retail chain to regulatory action as the Data Fiduciary.

Under the DPDPA, you are the Data Fiduciary. You carry the legal responsibility. The fact that a vendor processed or lost the data does not transfer your liability -it may create a contractual right of recovery, but regulators will come to you first.

Every vendor who touches personal data on your behalf is a Data Processor. The DPDPA requires a contractual relationship with each one mandating their compliance. This means auditing your current vendor stack, renegotiating agreements, and - for cross-border data flows - ensuring transfers meet the government’s prescribed conditions.

2019The year most Indian companies last reviewed their vendor data-sharing agreements. Those contracts were written for a world that no longer exists legally.

The cross-border dimension is especially live for companies using AWS, Google Cloud, Salesforce, SAP, or any SaaS platform headquartered outside India. Blacklist notifications, when they come, will require rapid contractual and technical restructuring.

BOARD-LEVEL ACTIONS THIS QUARTER

→  Create a data processor inventory - every vendor, platform, and tool that handles personal data.

→  Issue updated Data Processing Agreements to all processors, including DPDPA compliance clauses.

→  Map cross-border data flows and identify exposure if the government restricts transfers to specific geographies.

→  Include DPDPA compliance as a vendor onboarding criterion going forward.

 

05

🟢 Forward Plan

SIGNIFICANT DATA FIDUCIARY  ·  GROWTH PLANNING

Are we - or will we soon be a Significant Data Fiduciary, and do we understand what that means for our DPO hire?

REAL-WORLD SCENARIO

A fast-growing fintech startup just crossed 1 crore registered users. The leadership team is focused on Series C fundraising and a Southeast Asia expansion. Nobody has read the section on Significant Data Fiduciaries. Within two quarters, they may be formally designated - triggering a DPO appointment, annual Data Protection Impact Assessments, algorithmic risk audits, and restrictions on overseas data transfers. This was not in the fundraising model.

The government designates Significant Data Fiduciaries (SDFs) based on volume of data processed, sensitivity of data, potential national security risk, and public order impact. Designated SDFs carry a materially higher compliance burden: a mandatory India-based DPO, periodic DPIAs, independent audits, and algorithmic risk assessments.

Growing companies often don’t see this coming until they’re inside the threshold. The time to plan for SDF obligations is before you are designated - not after a government notification lands and you have 90 days to restructure your compliance architecture.

DPO + DPIASignificant Data Fiduciaries must appoint a Data Protection Officer based in India and conduct annual Data Protection Impact Assessments; costs that belong in your strategic plan now.

The DPO is not an honorary title. The contact information must be publicly available, the role requires genuine authority, and the officer must be equipped to represent the organisation before the Data Protection Board.

BOARD-LEVEL ACTIONS THIS QUARTER

→  Model your data footprint against known SDF criteria: volume, sensitivity, sector risk.

→  Begin scoping the DPO role now: skills required, reporting line, budget, public-facing mandate.

→  Build DPIA capability internally or through a retained privacy advisor; don’t wait for designation.

→  Factor SDF compliance costs into your 3-year financial model and investor disclosures.

The Window Is Open. It Will Not Stay Open.

The phased implementation runs to May 2027. That is not an invitation to wait; it is a runway to get organised. Companies that use this period to build genuine data governance infrastructure will be ahead of their competition, more attractive to global partners, and far better insulated from enforcement risk.

Companies that treat DPDPA as they treated GST in 2016, something to scramble for at the last minute, will face the same chaos, except the fines here don’t cap at a few lakhs. They run to hundreds of crores, and in criminal cases, to prison sentences for directors.

The five questions above are a starting point, not a checklist. If you’re not sure where your organisation stands on any of them; that is, itself, the answer.

About the Author

Jayshree Murarka is Associate Director at Zou Global Services, where she leads data privacy and compliance advisory engagements. A qualified lawyer and data privacy professional, she advises Indian and multinational organisations on navigating the Digital Personal Data Protection Act, 2023, GDPR, and cross-border privacy frameworks. She writes regularly on the practical compliance questions that legal and compliance heads face as India's privacy regime takes shape.

Disclaimer: This article has been prepared for general information. It does not constitute legal advice. For jurisdiction-specific guidance, consult your data privacy counsel.